Nonproliferation, Antiterrorism and Cyber · 3 of 3
Cyberspace and digital connectivity assistance
In short
- Assistance may go to foreign governments and to national, regional and international institutions.
- Foreign law enforcement and military personnel may join non-military activities.
- Funds are obligated under the reprogramming notification procedures.
1. Why Congress added a cyber part
The newest assistance part of the Foreign Assistance Act is Part X of its military assistance and sales subchapter in the Code. It was added by Public Law 118-31 in December 2023, under the title Cyberspace, Digital Connectivity, and Related Technologies (CDT) Fund. Congress opened it with four findings (22 U.S.C. 2349cc).
The findings describe a shared exposure. Increasingly digitized and interconnected social, political and economic systems have introduced new vulnerabilities for malicious actors to exploit, threatening economic and national security. The rapid spread of information and communication technologies brings mounting risks of accidents and malicious activity. Because those technologies are manufactured, traded and networked globally, United States security depends greatly on the cybersecurity practices of other actors, including other countries. Congress found that assistance to bolster civilian capacity abroad can reduce vulnerability in the technology ecosystem and advance national and economic security objectives (22 U.S.C. 2349cc).
2. What the Secretary of State may fund
The Secretary of State may provide assistance to foreign governments and organizations, including national, regional and international institutions, on terms the Secretary determines (22 U.S.C. 2349cc-1(a)). The assistance serves four aims. It may "advance a secure and stable cyberspace" and protect and expand trusted digital ecosystems and connectivity. It may also build the cybersecurity capacity of partner countries and organizations.
The fourth aim concerns values. Assistance may help ensure that the development of standards, and the deployment and use of technology, support and reinforce human rights and democratic values. The statute names the Digital Connectivity and Cybersecurity Partnership as one channel for that work (22 U.S.C. 2349cc-1(a)).
3. The programs the statute lists
The permitted uses fall into three groups plus a residual category (22 U.S.C. 2349cc-1(b)). The first group is infrastructure and markets. Programs may advance the adoption and deployment of secure and trustworthy information and communications technology (ICT) infrastructure and services. That includes efforts to grow global markets for secure ICT goods and services and to promote a more diverse and resilient ICT supply chain.
The second group is technical and capacity building assistance on policy. It covers regulatory frameworks that create an enabling environment for digital connectivity and a vibrant digital economy. It also covers technology developed, deployed and used in ways that support democratic values and human rights, the promotion of innovation and competition, and digital governance built on rights-respecting international norms and standards.
The third group helps countries prepare for, defend against and respond to malicious cyber activities. The statute lists eleven forms this can take. They include adopting cybersecurity best practices, developing national strategies, and deploying tools and services to increase the security, strength and resilience of networks and infrastructure. They also include building watch, warning, response and recovery capabilities, such as cybersecurity incident response teams, and collaboration with the Cybersecurity and Infrastructure Security Agency (CISA) and other federal agencies.
The same list reaches law enforcement and diplomacy. It includes programs to strengthen partner governments’ capacity to detect, investigate, deter and prosecute cybercrimes. It also includes information and resources for diplomats in negotiations on international law and cybersecurity capacity building measures. Collective action against shared threats, the Framework of Responsible State Behavior in Cyberspace and the fortification of deterrence instruments in cyberspace complete the list. The Secretary of State may also designate other purposes and functions (22 U.S.C. 2349cc-1(b)).
4. Decisions and annual justification
Policy decisions rest with the Secretary of State (22 U.S.C. 2349cc-1(c)). The Secretary decides whether there will be cybersecurity and digital capacity building programs for a foreign country or an entity operating there. The Secretary also decides the amount of funds for each country or entity, and the scope and nature of the uses.
Each year the Secretary must provide a detailed justification for the uses and purposes of the amounts provided under the part (22 U.S.C. 2349cc-1(d)). It must cover the amounts and kinds of grants, of any budgetary support, and of project assistance, with the purposes each serves. The authority does not preclude using funds provided under other authorities that are also available for the same purposes (22 U.S.C. 2349cc-1(e)).
5. Law enforcement, military personnel and international bodies
The part is civilian in focus, but it does not exclude security forces entirely. Appropriated amounts may be used, notwithstanding any other provision of law, "to strengthen civilian cybersecurity and information and communications technology capacity" (22 U.S.C. 2349cc-1(f)). That use can include participation of foreign law enforcement and military personnel in non-military activities. The funds may also go as contributions to international organizations and international financial institutions of which the United States is a member.
A condition attaches to that support. It must be essential to enabling civilian and law enforcement cybersecurity and ICT activities in the countries concerned (22 U.S.C. 2349cc-1(f)). The list of permitted programs refers back to this rule, allowing capacity building for cybersecurity partners that include law enforcement and military entities as it describes (22 U.S.C. 2349cc-1(b)).
6. Notice to Congress before funds are obligated
Funds under the section must be obligated in accordance with the procedures that apply to reprogramming notifications under the Act (22 U.S.C. 2349cc-1(g)). Those procedures generally bar obligating funds for activities, programs, countries or other operations not justified to Congress, or in excess of the amount justified, without advance notice. The notice goes to four committees fifteen days before the obligation. They are the Senate Committee on Foreign Relations, the House Committee on Foreign Affairs and the Appropriations Committees of both houses (22 U.S.C. 2394-1(a)).
7. Emergency support and funding
The part also looks at crisis response. The Secretary of State is authorized to conduct a review, in consultation with other federal departments and agencies as appropriate. It examines the capacity of the United States Government to deliver emergency support promptly and effectively to countries experiencing major cybersecurity and ICT incidents (22 U.S.C. 2349cc-2(a)). The review is to identify the factors constraining that support. It is also to develop a strategy to improve coordination among federal agencies and resolve those constraints.
The results were due to Congress not later than one year after December 22, 2023. The report goes to the Senate committees on Foreign Relations and on Homeland Security and Governmental Affairs. It also goes to the House committees on Foreign Affairs and on Oversight and Accountability (22 U.S.C. 2349cc-2(b)).
The funding authorization is $150,000,000 during the five-year period beginning on October 1, 2023, to carry out the purposes of the part (22 U.S.C. 2349cc-3).
Key terms
| CDT Fund | The title of the part covering assistance for cyberspace, digital connectivity and related technologies. |
|---|---|
| ICT | Information and communications technology, the infrastructure and services the part seeks to make secure and trustworthy. |
| Incident response team | A partner capability for cybersecurity watch, warning, response and recovery that the part may help develop. |
| Reprogramming notification | Advance notice to four congressional committees before funds are obligated outside the amounts justified to Congress. |
| Framework of Responsible State Behavior in Cyberspace | The framework whose advancement is among the listed program purposes. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Digital and physical security go together for programs that operate in difficult places. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.